Courseiva

CISM Information Security Program Practice Question

A security manager is reviewing the organization's information security strategy and notices that it focuses heavily on technology controls but lacks integration with business processes. Which action should the manager take to improve alignment with business objectives?

⚠ Common exam trap

The trap here is opting for more technology, training, or staff when the core issue is a lack of integration between security and business processes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct a gap analysis to identify where security processes are not integrated with business processes

Conducting a gap analysis is the most appropriate action because it systematically identifies where security is not integrated with business processes. This understanding enables the manager to develop targeted initiatives to embed security into business operations, ensuring that security supports and enables business objectives. The gap analysis should be collaborative, involving business stakeholders to accurately capture requirements and priorities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase the budget for security technology to cover more advanced tools

    Why it's wrong here

    Increasing the technology budget without addressing the lack of business integration would exacerbate the misalignment. The issue is not the amount of technology but how it supports business objectives. Adding more tools may create complexity and cost without improving alignment. The manager should instead focus on embedding security into business processes and ensuring that technology investments are driven by business risk and requirements, not the other way around.

  • ✗

    Hire additional security staff to monitor and respond to incidents more effectively

    Why it's wrong here

    Hiring more staff improves operational capacity but does not fix the strategic disconnect. The organization may become better at responding to incidents, but without integration, security will remain reactive and may not address the root causes of risk. The manager should focus on aligning security with business processes to proactively manage risk and support business goals. Staffing increases should follow a clear strategy that includes business integration.

  • ✓

    Conduct a gap analysis to identify where security processes are not integrated with business processes

    Why this is correct

    A gap analysis will pinpoint specific areas where security is disconnected from business processes, providing a roadmap for integration. It helps the manager understand which business functions lack security considerations and prioritize efforts to embed security into those areas. This approach ensures that security becomes an enabler of business objectives rather than a standalone technical function. The gap analysis should involve stakeholders from both security and business units to ensure comprehensive insights.

  • ✗

    Implement a new security awareness program to educate employees about security policies

    Why it's wrong here

    While awareness is important, it does not directly address the strategic misalignment between security and business processes. The problem is structural: security is not woven into how the business operates. Awareness programs can support a culture of security, but they are not a substitute for integrating security into business workflows, decision-making, and project management. The manager should first identify and close the integration gaps before rolling out awareness initiatives.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.